CVE-2026-26110

8.4

Microsoft · Office

A type confusion vulnerability in Microsoft Office allows an unauthorized attacker to execute arbitrary code locally on the affected system.

Executive summary

A critical type confusion vulnerability in Microsoft Office products exposes users to potential local code execution by unauthorized attackers.

Vulnerability

This vulnerability is a type confusion flaw (CWE-843) that occurs when the application accesses a resource using an incompatible type. The vulnerability allows an unauthorized attacker to trigger code execution on the local host.

Business impact

Successful exploitation of this vulnerability permits an attacker to execute arbitrary code with the privileges of the logged-in user, potentially leading to full system compromise. Given the CVSS score of 8.4, this poses a significant risk to data confidentiality, integrity, and availability, as unauthorized access to sensitive documents and credentials stored within the Office environment becomes possible.

Remediation

Immediate Action: Apply the relevant security updates provided in the Microsoft Security Update Guide immediately to remediate the vulnerability.

Proactive Monitoring: Monitor endpoint activity for suspicious file execution or unauthorized child processes spawned from Office applications.

Compensating Controls: Restrict access to untrusted document formats and utilize endpoint protection solutions to detect and block malicious payloads associated with Office exploitation.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations should prioritize the deployment of the vendor-supplied patches across all affected Office installations. Given the severity of the potential impact, administrators should verify successful update installation across all endpoints to eliminate the risk of local code execution.

More Microsoft CVEs

Sources